I have not setup a VPN server before. My understanding may be incorrect, but from what I've found regarding OEM ASUSWRT firmware, VPN is protected by a username/password authentication only. If this is true, then I don't follow how it is more secure to expose an entire LAN based on username/password (on a known port) than to expose a random port (not 80 or 8080) to access just the router web interface.
I admit that the idea of having access to my LAN is enticing. If I could enable this with more powerful authentication I'd do it. Is there support for signed certificates, similar to what I've used for https? My understanding is that this is the only way to prevent spoofing and ensure that when I think I'm authenticating with my VPN server (router) I am actually communicating with it (encrypted not clear text).
Is this possible with ASUSWRT? Am I on the right track, or is my understanding of how VPN authentication works incorrect?
I admit that the idea of having access to my LAN is enticing. If I could enable this with more powerful authentication I'd do it. Is there support for signed certificates, similar to what I've used for https? My understanding is that this is the only way to prevent spoofing and ensure that when I think I'm authenticating with my VPN server (router) I am actually communicating with it (encrypted not clear text).
Is this possible with ASUSWRT? Am I on the right track, or is my understanding of how VPN authentication works incorrect?